Review AWS default VPC configuration

Check whether the default VPC’s actual subnets, routes, and security groups meet operational requirements.

Description

A default VPC still needs subnets, routes, and security groups managed to meet organizational requirements. A default VPC is not inherently insecure, but relying on its initial configuration without review can leave unnecessary public paths.

aws_default_vpc manages the default VPC through Terraform. Its presence alone does not establish that workloads use the VPC or that network controls are absent.

Potential impact

  • Insufficient network controls: unreviewed subnet, routing, or security group settings can permit unintended access.
  • Inconsistent operations: network layouts may be harder to manage consistently across environments.
  • Resource exposure: deployments that rely on defaults can include unnecessary public configurations.

Remediation

  • Review the default VPC’s subnets, internet routes, and security groups, and apply the required controls.
  • If separate network isolation is needed, define a dedicated VPC with aws_vpc and design its subnets and access policies together.
  • Plan migration and connectivity before retiring or deleting a default VPC used by existing resources.

Examples

Manage the default VPC

hcl
resource "aws_default_vpc" "example" {
  tags = {
    Name = "Default VPC"
  }
}

Define a separate VPC

hcl
resource "aws_vpc" "example" {
  cidr_block       = "10.0.0.0/16"
  instance_tenancy = "default"

  tags = {
    Name = "main"
  }
}

The first example manages the default VPC; the second defines a separate VPC. Declaring a separate VPC does not migrate existing resources or restrict access by itself. Configure subnets, routes, and security policies to suit the workload.

References